2026 CVE Vulnerabilities

60,210 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8823LOW3.8Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests whi...
CVE-2026-8646CRITICAL9.1IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 ar...
CVE-2026-8636HIGH7.5IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve use...
CVE-2026-8059MEDIUM6.1IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site script...
CVE-2026-7664CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and...
CVE-2026-7253MEDIUM6IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send ...
CVE-2026-56104HIGH8.8Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and i...
CVE-2026-54268HIGH7.5Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54267MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54266MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54265MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54264MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-53655MEDIUM5.5node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= recor...
CVE-2026-53550MEDIUM5.3js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithm...
CVE-2026-52725MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50557MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50178HIGH8.8The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side...
CVE-2026-49241HIGH8.8The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4...
CVE-2026-41049HIGH7.1Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed a...
CVE-2026-41048HIGH7.1Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local at...
CVE-2026-41047MEDIUM5.5Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacke...
CVE-2026-41046HIGH7.3A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to...
CVE-2026-41045HIGH7A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass...
CVE-2026-12725MEDIUM5.9A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of...
CVE-2026-12628CRITICAL9.1IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now